Chapter 33: Access Control Lists
STANDARD Revision 1.0
C4® CMTS Release 8.3 User Guide
© 2016 ARRIS Enterprises LLC. All Rights Reserved.
953
In-band Management
The ARRIS C4/c CMTS offers enhanced in-band network management with controlled access to the SCM via standard
Access Control Lists (ACLs) for C4/c CMTS administrators.
Note: The SCM Access feature does not support IPv6 ACLs.
Provision In-band Management
To provision in-band management, permit and define a standard ACL by entering:
configure access-list 1 permit any
configure interface gigabitethernet 6/0 ip inband access-group 1
This feature provides:
o
IP connectivity to the SCM through the client cards (CAMs) and RCM.
o
The ability to permit or deny access to the SCM from specified subnet or host addresses.
o
Access to the SCM via the SCM loopback IP address.
An ACL must be applied to an ingress interface with "permit-access" functionality to allow access to the SCM.
Use the following command to apply an IPv4 ACL to a specific Gigabit Ethernet or ten-Gigabit Ethernet interface. If an
ACL is applied to a physical port, it is active for all virtual routes associated with that physical port:
configure [no] interface {gigabitEthernet | tengigabitEthernet} <slot/port> ip scm access-group
<acl-index>
Note: Only one SCM Access ACL can be applied to a given physical interface. If you apply a second SCM Access ACL to an
interface, it replaces the first one. This differs from previous software releases in which multiple ACLs applied to the same
interface would function as one long concatenated access list. The SCM Access ACL can be in addition to a dataplane ACL,
but the dataplane ACL takes precedence over the SCM Access ACL. Also, SCM Access Lists must use standard IPv4 ACLs.
Note: SCM access via the Front Ethernet Port is restricted to locally connected hosts when this feature is active and at least
one network interface is in-service.
The configuration example below creates a standard access list number 1. Access list 1 is named In-Band Management. A
permit all rule is added to access list 1 to allow all hosts to connect to the chassis console. Another ACL, extended acl